Back to skill

Security audit

Poyo Boost Music Style

Security checks for vulnerabilities and agentic risk

Overview

The skill bundle performs operational and administrative work, but the sensitive actions are disclosed and generally scoped to user-directed workflows.

Install only if you expect your agent to help with Axiom/Sentry observability, dashboards, ClawHub staff workflows, releases, and related code review tasks. Use least-privilege API tokens, review commands before writes, and be careful with the SRE memory feature because it can persist operational findings and share org memory when configured.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.